That's why you use them just as dumb pipes forwarding encrypted data traffic from one place to another.
No SMS, no phone calls if you can avoid it.
How often do PCC servers reboot and wipe the temporary encryption key?
It doesn't actually say there is no persistent storage, it says that the compute node will not store it for longer than the request. There's nothing to stop the data coming from a datastore outside of the "PCC" in another part of apple's infrastructure.
Apple deserves credit for correctly analyzing their threat model and designing their system accordingly.
Would this work in some authoritarian countries? No and Apple doesn't care. Would it work in a western one? Maybe.
If pressured by the government, Apple can simply change the client software to loosen the attestation requirements for private compute. And that would be the most inconspicuous choice.
"oh it's our dev version ? what's the problem ? we need data access for troubleshooting"
70,000+ Apple user accounts are surveilled in this manner every year.